ZeroHour

CVE-2019-2249

CVSS 3.1
9.8 critical
EPSS
1%p71
Published
()
Modified
Description

Kernel can do a memory read from arbitrary address passed by user during execution of a syscall in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in IPQ8074, MDM9205, MDM9650, QCA8081, QCS605, SD 427, SD 435, SD 450, SD 625, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 835, SD 845 / SD 850, SD 855, SD 8CX, SDA660, SDM630, SDM660, SDX20, Snapdragon_High_Med_2016, SXR1130

Vendors
qualcomm
Products
ipq8074 firmware, mdm9205 firmware, mdm9650 firmware, qca8081 firmware, qcs605 firmware, sd 427 firmware, sd 435 firmware, sd 450 firmware, sd 625 firmware, sd 636 firmware, sd 665 firmware, sd 675 firmware
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.